Executive brief
Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a critical security vulnerability in its Content Server component. An unauthenticated attacker can exploit this over the network to gain full access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical company records and intellectual property.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware) is classified as improper access control (CWE-284). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. It does not require user interaction or elevated privileges. Successful exploitation grants the attacker the ability to perform unauthorized creation, deletion, or modification of critical data, as well as providing complete read access to all data accessible by the WebCenter Content instance. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory